Security · AWS + Claude
Supplier Risk Review
A first pass at every supplier's security posture, done for you. It gathers what each supplier has on file, flags what is missing, and sorts everyone by risk, so each review starts at step two. Security still makes the call.
How it all connects
Where the data comes from and how it flows into this view. Hover to trace a path; click any box to see what it does.
Why a gap is a bad thing
When a supplier is missing a key document, like a signed BAA or a current SOC 2, we are trusting them with our data on their word alone. If they have a breach, we may share the blame, the reporting duty and the cost. The worst gaps show up in red.
Why this is a good thing
Instead of an analyst spending hours reading paperwork before the real review can start, the reading is already done. Everyone is sorted by how much risk they carry, so the team spends its time on the suppliers that actually need it. The strong ones show up in green.
What happens next
- Chase the red items first: missing BAAs and expired or stale reports.
- Request current reports from each supplier trust center.
- Confirm scope: which suppliers actually touch regulated data.
- Security reviews each first pass and signs off.
| Supplier | Risk tier ? | SOC 2 ? | ISO 27001 ? | HITRUST ? | BAA ? | Control coverage ? | Handles PHI ? | Source conf. ? | Review |
|---|---|---|---|---|---|---|---|---|---|
| Thoropass | Critical | Unknown | Unknown | Unknown | Missing | 45% | Yes | Low | Review → |
| HealthVerity | High | Unknown | Unknown | Unknown | Missing | 60% | Yes | Medium | Review → |
| Welltality | High | Unknown | Unknown | Unknown | In review | 20% | Yes | Medium | Review → |
| Veradigm | High | Type II | Unknown | Unknown | Missing | 60% | Yes | Medium | Review → |
| MD Revolution | High | Unknown | Unknown | Unknown | In review | 30% | Yes | Medium | Review → |
| Highmark | High | Unknown | Unknown | HITRUST | Compliant | 35% | Yes | Low | Review → |
| Optum Insight | High | Unknown | ISO 27001 | Unknown | In review | 65% | Yes | Medium | Review → |
| Optimize Health | Medium | Type II | Unknown | Unknown | Missing | 75% | Yes | Medium | Review → |
| BambooHR | Medium | Type II | ISO 27001 | Unknown | Missing | 75% | Yes | Medium | Review → |
| NetSuite | Medium | Type II | ISO 27001 | Unknown | Missing | 80% | Yes | High | Review → |
| HubSpot | Medium | Type II | No | Unknown | Missing | 85% | Yes | High | Review → |
| UiPath | Medium | Type II | ISO 27001 | HITRUST | Missing | 85% | Yes | Medium | Review → |
| Oracle | Medium | Type II | ISO 27001 | Unknown | Missing | 88% | Yes | Medium | Review → |
| Box | Medium | Type II | ISO 27001 | Unknown | Missing | 88% | Yes | High | Review → |
| DocuSign | Medium | Type II | ISO 27001 | Unknown | Missing | 90% | Yes | High | Review → |
| Definitive Healthcare | Medium | Type I | Unknown | Unknown | Missing | 45% | No | Medium | Review → |
| Accuhealth | Low | unknown | Unknown | Unknown | Compliant | 35% | Yes | Medium | Review → |
| Smart Meter | Low | Type II | Unknown | Unknown | Compliant | 70% | Yes | High | Review → |
| Tenovi | Low | Type II | Unknown | Unknown | Compliant | 70% | Yes | High | Review → |
| Waystar | Low | Type II | Unknown | HITRUST | Compliant | 85% | Yes | High | Review → |
| Domo | Low | Type II | ISO 27001 | HITRUST | Compliant | 85% | Yes | High | Review → |
| Five9 | Low | Type II | ISO 27001 | Unknown | Compliant | 85% | Yes | High | Review → |
| Monday.com | Low | Type II | ISO 27001 | Unknown | Compliant | 88% | Yes | High | Review → |
| Twilio | Low | Type II | ISO 27001 | Unknown | Compliant | 90% | Yes | High | Review → |
Thoropass
In plain terms
As a compliance platform it holds a company's most sensitive audit evidence and system connections, so a breach there could hand attackers a roadmap to that company's security gaps and connected systems.
Compliance is Thoropass's core business and it employs its own accredited auditors, so it is highly incentivized and equipped to keep its own house in order.
Certifications (public)
BAA & contract (from our records)
What we found
- Thoropass is itself a compliance vendor (formerly Laika): an AICPA peer-reviewed firm, a PCI QSA, and a HITRUST Accredited Assessor.
- It provides SOC 1/SOC 2, ISO 27001, HITRUST, PCI DSS, HIPAA, and GDPR audit/attestation services to its own customers.
- It runs a public Trust Center that lets companies (including Thoropass) display audits and gate private documents behind an in-portal NDA.
- Its own platform-level SOC 2 Type II and ISO 27001 status could not be independently verified from public sources; treat as unknown pending report request.
- As a compliance platform it ingests customers' sensitive control evidence, policies, and potentially regulated data via 100+ integrations.
Checklist: what might need doing
- Request Thoropass's own SOC 2 Type II report and ISO 27001 certificate directly via trust.thoropass.com (likely NDA-gated).
- Confirm which frameworks Thoropass itself is certified against vs. which it merely offers as a service to clients (do not conflate the two).
- If PHI or regulated evidence will be uploaded, sign a BAA and review integration/data-handling scope.
- Verify current audit periods and independence of the auditor for Thoropass's own attestations.
First-pass summary
Thoropass is itself a compliance-automation vendor (accredited AICPA firm, PCI QSA, HITRUST assessor) that sells SOC 2/ISO/HITRUST/PCI/HIPAA services and runs a Trust Center. Its own platform-level certifications (SOC 2 Type II, ISO 27001) were not independently verifiable from public search and are marked unknown pending a direct report request. Because it aggregates highly sensitive compliance evidence, confirm its own attestations before relying on it.
Compiled from public sources (www.thoropass.comtrust.thoropass.comwww.thoropass.comwww.soc2certification.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
HealthVerity
In plain terms
If their controls fell short, sensitive health data they link and match on behalf of clients could be exposed or re-identified, which would be a privacy breach affecting patients.
They run a government-grade (FedRAMP) secure environment and have had experts formally verify their privacy protections, and they destroy project data on a strict timeline.
Certifications (public)
BAA & contract (from our records)
What we found
- Operates a FedRAMP-Moderate-certified cloud environment for its Identity Manager solution (used by NSF/NCSES).
- Privacy architecture publicly described as HIPAA-compliant via expert determination by Dr. Brad Malin (Vanderbilt); business model centers on de-identified/tokenized real-world health data rather than raw PHI.
- For its NSF engagement, project data were isolated and destroyed within 30 days of delivery with a formal Certificate of Destruction.
- No public evidence of SOC 2, HITRUST, or ISO 27001 was found; absence of a formal trust center listing these is itself a review gap.
Checklist: what might need doing
- Request current SOC 2 Type II report (or confirm none exists)
- Ask whether they hold HITRUST or ISO 27001
- Obtain the HIPAA expert-determination letter / privacy methodology
- Execute a BAA if any identifiable PHI will flow
- Confirm subprocessor list and data-destruction terms in the contract
- Request their FedRAMP Moderate authorization scope/ATO details
First-pass summary
HealthVerity is a healthcare real-world-data and identity-resolution vendor that publicly leans on FedRAMP Moderate authorization and expert-determination HIPAA compliance rather than SOC 2/HITRUST, which were not verifiable from public sources. Its model favors de-identified/tokenized data, but it still touches regulated health data, so a BAA and direct evidence requests are warranted. Coverage is moderate pending confirmation of standard commercial attestations.
Compiled from public sources (healthverity.comblog.healthverity.comhealthverity.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Welltality
In plain terms
This is a small company that only says it follows HIPAA on its own say-so, so if their controls are thin, sensitive patient wellness and eligibility data could leak with little independent oversight to have caught it.
They do publicly acknowledge they handle patient data under HIPAA and describe ongoing internal auditing, so security is at least on their radar.
Certifications (public)
BAA & contract (from our records)
What we found
- Small vendor. Welltality Health (welltalityhealth.com), Jacksonville FL; focus is Annual Wellness Visits, Health Risk Assessments, Chronic Care Management and its 'Wellassessment' preventive-care software rather than device-based RPM.
- Only public security statement is a HIPAA self-attestation ('all systems are audited in compliance with HIPAA on an ongoing basis'); wording implies self-assessment, not an independent audit.
- No SOC 2, HITRUST, or ISO 27001 mentioned anywhere public. No trust center or security page.
- Clearly handles PHI (patient assessments, eligibility checks, care-gap analytics on behalf of practices/payers), so BAA is required.
- Minimal public security footprint overall — itself a notable finding for a PHI-handling vendor.
Checklist: what might need doing
- Send full security questionnaire (e.g. SIG-lite or CAIQ) — public info is insufficient for a decision.
- Determine whether any INDEPENDENT audit exists (SOC 2 / HIPAA Security Rule assessment) or if 'audited' means self-assessment only.
- Require a signed BAA before any PHI exchange.
- Ask about encryption at rest/in transit, hosting, access controls, breach history, and cyber-insurance.
- Given small-vendor profile, weight concentration/business-continuity risk in the review.
First-pass summary
Welltality is a small Jacksonville-based wellness/AWV/CCM software vendor with almost no public security posture — only a self-stated HIPAA compliance line, no SOC 2/HITRUST/ISO, and no trust center. It handles PHI, so the thin public footprint is itself a risk flag. A full security questionnaire and BAA are required before onboarding.
Compiled from public sources (www.welltalityhealth.comwww.welltalityhealth.comwww.welltalityhealth.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Veradigm
In plain terms
As an electronic health record vendor they hold detailed patient medical records, so a security failure could directly expose sensitive clinical information for many patients.
They maintain an independent SOC 2 Type II report, healthcare-specific EHNAC accreditation, e-prescribing (EPCS) certification, and a 24/7 security operations center.
Certifications (public)
BAA & contract (from our records)
What we found
- Security program page cites SOC 2 Type 2 reports, EHNAC accreditation, EPCS certifications, and ISO 9001:2015 reviews.
- Certified products meet ONC Certification Rule security requirements; operates a 24x7 Security Operations Center.
- Formerly Allscripts; rebranded to Veradigm in 2022 (EHR, practice management, patient engagement products) — clearly handles PHI, so a BAA is required.
- No public evidence of HITRUST or ISO 27001.
- Business-continuity note (non-security): Veradigm faced financial-reporting/restatement issues and was delisted from Nasdaq to OTC markets around 2024 — worth flagging for vendor viability, not directly a security control.
Checklist: what might need doing
- Request current SOC 2 Type II report
- Ask whether they hold HITRUST or ISO 27001 (not publicly listed)
- Request EHNAC accreditation and EPCS certification evidence
- Execute a BAA
- Confirm subprocessor list and breach-notification terms
- Assess vendor financial viability given the Nasdaq delisting / restatement history
First-pass summary
Veradigm (formerly Allscripts) is an EHR and health-IT vendor whose public security page confirms SOC 2 Type II, EHNAC, EPCS, and ISO 9001, with products meeting ONC certification requirements. It handles PHI, so a BAA is required. HITRUST/ISO 27001 are not publicly evidenced, and separately its 2024 Nasdaq delisting/restatement history is worth a vendor-viability check.
Compiled from public sources (veradigm.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
MD Revolution
In plain terms
Because they now sit inside a larger merged company with no published security certification, we can't confirm who is actually accountable for protecting our patients' data or how well they do it.
The platform is marketed as HIPAA-compliant and runs on Amazon's cloud, and the vendor now backs a much larger, better-resourced remote-care organization.
Certifications (public)
BAA & contract (from our records)
What we found
- CORPORATE CHANGE: MD Revolution was acquired by CoachCare (announced June 23, 2025). RevUp/RevCare now operate under CoachCare; mdrevolution.com redirects to CoachCare branding. Contract/BAA counterparty may now be CoachCare.
- RevUp is described as a HIPAA-compliant chronic care management + RPM platform; CoachCare platform is described as HIPAA-compliant and hosted on AWS.
- No public SOC 2, HITRUST, or ISO 27001 evidence found for either MD Revolution or CoachCare.
- No dedicated public trust center or security page located.
- Combined entity reportedly serves 250+ healthcare organizations and 500k+ patients, so it handles PHI at scale.
Checklist: what might need doing
- Confirm the correct legal contracting entity post-acquisition (MD Revolution LLC vs CoachCare) and get a fresh/assigned BAA.
- Request any SOC 2 Type II report for the RevUp/RevCare platform under CoachCare ownership.
- Ask about HITRUST or an independent HIPAA Security Rule assessment.
- Confirm data hosting region, encryption, and subprocessor list given the AWS hosting statement.
- Reassess vendor as 'CoachCare' in the risk register, not standalone MD Revolution.
First-pass summary
MD Revolution's RevUp/RevCare RPM+CCM platform is marketed as HIPAA-compliant and AWS-hosted, but no SOC 2, HITRUST, or ISO evidence is public. Critically, MD Revolution was acquired by CoachCare in mid-2025, so the contracting entity and BAA counterparty should be re-verified. Treat security posture as unverified pending a report request.
Compiled from public sources (mdrevolution.commdrevolution.comwww.coachcare.comhitconsultant.netwww.coachcare.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Highmark
In plain terms
Highmark is a health insurer holding huge amounts of members' medical and personal information, so any security gap could expose sensitive health records for a very large population.
A key Highmark division has passed HITRUST, the toughest healthcare security certification, and the company is a mature, heavily-regulated insurer with an established security program.
Certifications (public)
BAA & contract (from our records)
What we found
- HM Health Solutions (Highmark Health subsidiary) achieved HITRUST CSF Certification for its main claims-processing systems and United Concordia Dental systems (PRNewswire announcement).
- As a health plan, Highmark is a HIPAA covered entity handling large volumes of PHI.
- Public breach trackers report a Highmark data breach in 2025 (breachsense.com); details not independently verified here.
- Highmark historically requires its own vendors to undergo HITRUST assessment (common among large payers).
Checklist: what might need doing
- Request Highmark's current SOC 2 Type II report and/or HITRUST certification letter directly (not publicly posted).
- Clarify which Highmark legal entity/system TWC actually contracts with (Highmark Health vs HM Health Solutions vs a plan subsidiary) since certs are scoped per entity.
- Obtain a signed BAA covering the specific data flow.
- Ask for details/remediation on the reported 2025 breach.
First-pass summary
Highmark Health is a large HIPAA-covered health plan; its HM Health Solutions subsidiary is publicly noted as HITRUST CSF certified, but Highmark does not publish a vendor-style trust center or SOC 2 report, so most posture must be confirmed via direct request. Because it is a payer handling PHI at scale, regulated-data exposure is inherent. Public reporting also references a 2025 breach that should be diligenced.
Compiled from public sources (www.prnewswire.comwww.highmarkhealth.orgwww.breachsense.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Optum Insight
In plain terms
This is the company behind the largest healthcare data breach ever (Change Healthcare, ~190 million people), so a control gap here has proven it can put enormous numbers of patient records at risk.
Their federal technology arm holds internationally recognized ISO 27001 (2022) information-security certification and top-tier CMMI process maturity, and post-breach they are under intense scrutiny and remediation.
Certifications (public)
BAA & contract (from our records)
What we found
- Optum Serve Technology Services publicly holds ISO/IEC 27001:2022, ISO/IEC 20000-1:2018, ISO 9001:2015, and CMMI Level 5 (Development and Services).
- MAJOR: Optum's subsidiary Change Healthcare suffered a February 2024 ransomware breach exposing data of roughly 190 million people — one of the largest healthcare breaches in US history. Root cause included a Citrix remote-access portal lacking multi-factor authentication and a nine-day detection delay; UnitedHealth's CEO testified security procedures had not been updated post-acquisition.
- The breach cost UnitedHealth Group an estimated ~$3.09 billion in direct costs.
- HITRUST and SOC 2 were not explicitly confirmed on the public pages reviewed; certifications are fragmented across Optum's many business units.
Checklist: what might need doing
- Identify the exact Optum legal entity/product you are contracting with and get its specific certifications (they vary by unit)
- Request current SOC 2 Type II and HITRUST status for that specific product
- Request post-Change-Healthcare remediation attestation and confirmation MFA is enforced on all remote access
- Execute a BAA
- Obtain breach-notification terms and subprocessor list
- Review any regulatory findings/OCR activity tied to the 2024 breach
First-pass summary
Optum (Optum Insight, part of UnitedHealth Group) is a large healthcare data/services vendor; its federal unit publicly holds ISO/IEC 27001:2022 and CMMI Level 5, but SOC 2/HITRUST were not confirmable at the enterprise level and certifications differ by business unit. The dominant risk factor is the February 2024 Change Healthcare breach (~190M people, MFA-less remote access, nine-day detection), which materially tempers its posture. It handles PHI, so a BAA and unit-specific evidence and remediation attestations are essential.
Compiled from public sources (business.optum.comhyperproof.iowww.trizettoprovider.comwww.security.org). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Optimize Health
In plain terms
This vendor runs remote patient monitoring, so it continuously collects patients' live health readings — a breach would leak ongoing clinical data tied to real patients.
They advertise an independent SOC 2 Type II audit, platform-wide HIPAA compliance with signed business-associate agreements, and strong encryption, which are the right baseline for a healthcare data handler.
Certifications (public)
BAA & contract (from our records)
What we found
- The optimize.health domain now 301-redirects to vivocaresolutions.com — Optimize Health appears to have rebranded/transitioned to Vivo Care Solutions; confirm the corporate/contracting entity.
- Security page claims SOC 2 Type II and platform-wide HIPAA compliance across RPM, CCM, and APCM, with BAAs signed with healthcare partners.
- HITRUST r2 is described as 'actively pursuing / in progress,' NOT yet certified on the current site.
- A 2022 Newswire release referenced Optimize Health achieving a HITRUST risk-based 2-year certification; this conflicts with the current 'in progress' status — needs reconciliation (may have lapsed or scope changed under rebrand).
- Encryption: TLS 1.2+ in transit, AES-256 at rest; MFA and least-privilege RBAC stated.
Checklist: what might need doing
- Confirm the legal entity TWC contracts with (Optimize Health vs Vivo Care Solutions) and get updated corporate docs after the apparent rebrand.
- Obtain the actual SOC 2 Type II report (not just the marketing claim) and check the audit period and any exceptions.
- Reconcile HITRUST status: get written confirmation of whether HITRUST is currently held (2022 release) or only in progress (current site).
- Execute/verify a current BAA under the new entity name.
First-pass summary
Optimize Health, a Seattle-based remote patient monitoring vendor, now redirects to Vivo Care Solutions, whose public security page claims SOC 2 Type II and platform-wide HIPAA compliance with BAAs and AES-256/TLS encryption. HITRUST is listed as in progress on the current site even though a 2022 press release announced HITRUST certification, so certification status needs to be reconciled directly. Because it handles live patient PHI, diligence on the actual SOC 2 report and the entity change is important.
Compiled from public sources (vivocaresolutions.comwww.newswire.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
BambooHR
In plain terms
BambooHR holds our employees' personal and payroll-adjacent data, so a breach there would expose staff Social Security numbers, salaries, and home addresses.
It carries the two most common security seals (SOC 2 Type II and ISO 27001) and gets audited every year by outside firms.
Certifications (public)
BAA & contract (from our records)
What we found
- SOC 2 Type II and ISO 27001 certified per vendor security page and trust center.
- Runs annual third-party penetration tests.
- Participates in EU-US / UK / Swiss-US Data Privacy Frameworks and offers a GDPR DPA.
- Not positioned as HIPAA-compliant; at least one third-party source states it does not meet HIPAA requirements. HITRUST not publicly confirmed.
- Detailed reports/certificates require registration + NDA acceptance in the trust center.
Checklist: what might need doing
- Register on trust.bamboohr.com, sign NDA, and pull the latest SOC 2 Type II report and ISO 27001 certificate.
- Confirm SOC 2 report date is current (within 12 months) and review any exceptions.
- Sign/execute the GDPR DPA if not already in place.
- Confirm scope: BambooHR is for employee PII, not PHI; do not route patient data through it.
- Verify HITRUST/HIPAA claims directly if any regulated data could enter the system.
First-pass summary
BambooHR is SOC 2 Type II and ISO 27001 certified with annual audits and penetration testing, and offers a GDPR DPA and DPF participation. It is an employee-PII system and is not marketed as HIPAA/HITRUST certified. Full documentation sits behind an NDA-gated trust center.
Compiled from public sources (www.bamboohr.comtrust.bamboohr.comwww.bamboohr.comthirdproof.ai). A production run reads the actual documents in the supplier folder. Security still makes the final call.
NetSuite
In plain terms
NetSuite runs the company's finances and ERP data, so a failure there could corrupt or leak financial records and disrupt accounting and audit readiness.
It carries a full stack of finance-grade security attestations (SOC 1, SOC 2 Type II, ISO 27001, PCI) backed by Oracle's audit program.
Certifications (public)
BAA & contract (from our records)
What we found
- SOC 1 Type II and SOC 2 Type II audited (SSAE18 / ISAE 3402).
- Certified to ISO/IEC 27001:2013, aligned with ISO 27018:2019; PCI DSS and PCI SSF compliant.
- Vendor materials also cite ISO 42001 (AI management) compliance.
- Customers may request the SOC 1, SOC 2 Type II report, ISO 27001 certificate and Statement of Applicability no more than once per year.
- Product is a financials/ERP system; commonly in SOX/financial-audit scope.
Checklist: what might need doing
- Request the current SOC 1 and SOC 2 Type II reports and ISO 27001 certificate + SoA via Oracle's annual request process.
- Confirm report periods are current and review complementary user-entity controls (CUECs) you must implement.
- Validate PCI DSS scope if card data is processed.
- Confirm data residency/region and encryption terms in the NetSuite Data Security Addendum.
- Not a PHI platform by default; confirm before storing any regulated health data.
First-pass summary
Oracle NetSuite maintains SOC 1 Type II, SOC 2 Type II, ISO 27001 (aligned to 27018), and PCI DSS/SSF, with reports provided to customers on request. As a financials/ERP platform it is typically in SOX scope. HITRUST is not publicly claimed for the NetSuite service itself.
Compiled from public sources (www.netsuite.comwww.oracle.comwww.netsuite.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
HubSpot
In plain terms
HubSpot is a marketing and CRM system holding customer and prospect contact details, so a gap could expose personal contact and communication data for everyone in TWC's pipelines.
HubSpot publishes an independent SOC 2 Type II audit and a public SOC 3, is built on ISO 27001-certified cloud infrastructure, and has strong GDPR tooling including EU data residency.
Certifications (public)
BAA & contract (from our records)
What we found
- HubSpot's own security page confirms a confidential SOC 2 Type II report and a publicly available SOC 3 report.
- ISO 27001 is held by HubSpot's cloud infrastructure providers (AWS), NOT by HubSpot itself per HubSpot's own legal/security page — do not credit HubSpot with its own ISO 27001.
- HubSpot is certified under the EU Cloud Code of Conduct (Level 2 mark) and offers EU (Frankfurt) data residency for GDPR.
- HubSpot's own page does NOT list HIPAA, HITRUST, or PCI DSS as HubSpot certifications; HubSpot is generally not intended for PHI and does not broadly sign BAAs (third-party trust aggregators listing 'HIPAA' should not be relied on over HubSpot's own docs).
- Bridge letters are available to cover gaps between SOC 2 Type II audit periods.
Checklist: what might need doing
- Do NOT put PHI into HubSpot — confirm HubSpot's PHI/BAA stance in writing; it is a marketing/CRM tool, not a healthcare-data platform.
- Request HubSpot's confidential SOC 2 Type II report (under NDA) and review the audit period/exceptions.
- If ISO 27001 is required, note HubSpot itself is not certified (only its infra) — decide if that is acceptable.
- Configure GDPR features (EU data residency, consent/subscription tracking) if EU personal data is stored.
First-pass summary
HubSpot holds its own SOC 2 Type II (confidential) and SOC 3 (public) and strong GDPR credentials, but ISO 27001 belongs to its AWS infrastructure rather than HubSpot itself, and HubSpot does not publicly claim HIPAA, HITRUST, or PCI DSS. It is a CRM/marketing platform for contact PII, not for PHI, so the main control is keeping regulated health data out of it. Confirm the SOC 2 report and PHI/BAA stance directly.
Compiled from public sources (legal.hubspot.comtrust.hubspot.comknowledge.hubspot.comtrustlists.org). A production run reads the actual documents in the supplier folder. Security still makes the final call.
UiPath
In plain terms
UiPath bots can be granted access to many internal systems, so a compromise could let an attacker act across every process the automation touches.
UiPath carries SOC 2 Type II, current ISO 27001:2022, and offers HIPAA-ready and FedRAMP editions for sensitive workloads.
Certifications (public)
BAA & contract (from our records)
What we found
- Holds SOC 2 Type II, ISO/IEC 27001:2022 (aligned to 27017/27018), and ISO 9001.
- HITRUST is referenced for UiPath's cloud offerings.
- HIPAA attestations apply to Automation Cloud Dedicated (not the general shared cloud).
- FedRAMP-compliant environment is specific to Automation Cloud Public Sector, using FIPS 140-2 validated encryption.
- Trust center is SafeBase-powered; documents typically require request/NDA.
- Compliance scope is tier-dependent: HIPAA/FedRAMP capabilities are tied to specific product editions.
Checklist: what might need doing
- Pull the SOC 2 Type II report and ISO 27001:2022 certificate from trust.uipath.com.
- Confirm which edition we use — HIPAA attestation requires Automation Cloud Dedicated; FedRAMP requires Public Sector.
- If bots handle PHI, ensure the Dedicated tier and a signed BAA are in place.
- Review bot credential/access scoping and least-privilege configuration on our side.
- Verify HITRUST scope directly against the trust center rather than third-party summaries.
First-pass summary
UiPath holds SOC 2 Type II and ISO/IEC 27001:2022 (plus 27017/27018 and ISO 9001), with HITRUST referenced for its cloud. HIPAA attestation is limited to Automation Cloud Dedicated and FedRAMP to the Public Sector edition, so regulated-data use depends on choosing the right tier. Documentation is available via the SafeBase-powered trust center.
Compiled from public sources (trust.uipath.comwww.uipath.comdocs.uipath.comdocs.uipath.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Oracle
In plain terms
Oracle cloud can host critical systems and sensitive data, so a lapse could take down business-critical services and expose whatever data lives there.
Oracle Cloud carries top-tier government-grade authorizations (FedRAMP High plus SOC 2, ISO 27001, HIPAA, PCI), among the most comprehensive available.
Certifications (public)
BAA & contract (from our records)
What we found
- OCI holds FedRAMP High authorization, HIPAA, ISO/IEC 27001, 27017, 27018, PCI DSS, and SOC 1/2/3.
- Performs annual compliance assessments, independent penetration tests, and third-party audits.
- Oracle publishes a broad cloud-compliance catalog spanning global and industry-specific frameworks (incl. GDPR, CSA STAR).
- Compliance is shared-responsibility: customer configuration affects whether their workloads inherit these controls.
- Oracle is a very large, diversified vendor; certification scope varies by specific product/service line.
Checklist: what might need doing
- Identify exactly which Oracle product/service is in scope; certifications differ across Oracle's portfolio.
- Pull the SOC 2 Type II report and ISO 27001 certificate for that specific service.
- If PHI is involved, execute an Oracle HIPAA BAA and confirm the service is in HIPAA scope.
- Review shared-responsibility guidance and confirm your own configuration meets control requirements.
- Confirm data region/residency and encryption/key-management terms.
First-pass summary
Oracle Cloud Infrastructure holds an extensive certification set including FedRAMP High, HIPAA, ISO 27001/27017/27018, PCI DSS, and SOC 1/2/3, with annual third-party audits. Because Oracle is a large multi-product vendor, confirm the specific service in scope, since certifications and BAA availability vary by product.
Compiled from public sources (www.oracle.comwww.ateam-oracle.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Box
In plain terms
Box stores documents that could include patient records or other sensitive files, so a misconfiguration or breach could expose PHI and trigger HIPAA reporting obligations.
Box is one of the most heavily certified content platforms available — FedRAMP High authorized, HIPAA-ready with a BAA, and built on ISO 27001 — making it well suited to sensitive data when configured correctly.
Certifications (public)
BAA & contract (from our records)
What we found
- Achieved FedRAMP High Authorization (ATO) in March 2025 via VA sponsorship, covering 400+ security controls; listed on the FedRAMP Marketplace.
- Supports HIPAA/HITECH and signs BAAs for Enterprise, Enterprise Plus, and Enterprise Advanced accounts (since 2013).
- ISMS built primarily on ISO 27001 and NIST 800-53; encryption strategy references HIPAA/HITECH, PCI DSS, ISO 27001; TLS 1.3 in transit.
- Additional government/regulated alignments cited: ITAR, DoD SRG IL4, NIST 800-171, FIPS 140-2, ISO 27018, IRS-1075.
- MFA over VPN and least-privilege access for systems supporting the Box service.
- HITRUST CSF certification not confirmed in public sources reviewed (marked unknown).
Checklist: what might need doing
- Sign a Box HIPAA BAA and confirm our account tier (Enterprise/Enterprise Plus/Advanced) supports it.
- Pull the current SOC 2 Type II report and ISO 27001 certificate from box.com/trust.
- Enable HIPAA-appropriate controls (restrict external sharing, enforce MFA/SSO, configure retention) — certification does not make our config compliant automatically.
- Confirm whether any workloads require the FedRAMP-authorized Box environment vs commercial.
- Verify HITRUST status directly if our review requires it, since it was not confirmed publicly.
First-pass summary
Box is a highly certified content-management platform: FedRAMP High authorized (2025), HIPAA/HITECH-capable with a signed BAA, ISO 27001-based ISMS, and SOC 2 reporting via its trust center, plus a broad set of government alignments. It is appropriate for sensitive documents including potential PHI provided a BAA is executed and sharing controls are configured. HITRUST CSF was not confirmed in the public sources reviewed.
Compiled from public sources (www.box.comwww.box.comsupport.box.comwww.fedramp.govwww.hipaajournal.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
DocuSign
In plain terms
This tool holds legally binding signed agreements, so if it were breached or misconfigured, sensitive contracts and the personal data inside them could be exposed or tampered with.
DocuSign carries the top mainstream security audits plus a U.S. government authorization, so it is a well-vetted, mature vendor for handling important documents.
Certifications (public)
BAA & contract (from our records)
What we found
- SOC 2 Type II covering security, availability, confidentiality, and processing integrity.
- ISO 27001:2022 plus ISO 27017 and ISO 27018 (cloud + PII in cloud) certified.
- FedRAMP Agency authorization; listed on the FedRAMP marketplace for federal eSignature/IAM and CLM.
- HIPAA-eligible with signed BAA and proper configuration; HIPAA is not an independent audit/certification.
- No public evidence of HITRUST certification found.
Checklist: what might need doing
- Request and review the current SOC 2 Type II report via the DocuSign Trust Portal.
- Execute a signed BAA before any PHI flows through DocuSign and confirm HIPAA-eligible configuration.
- Confirm whether the specific DocuSign product/plan purchased is in scope of the certifications (federal vs commercial tiers differ).
- Verify ISO 27001 certificate currency and scope.
First-pass summary
DocuSign is a mature, heavily certified e-signature/agreement vendor holding SOC 2 Type II, ISO 27001:2022 (plus 27017/27018), and FedRAMP Agency authorization. It supports HIPAA via BAA but HIPAA and HITRUST are not independently confirmed as certifications. Strong posture; standard controls apply for regulated data.
Compiled from public sources (www.docusign.comwww.docusign.comwww.docusign.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Definitive Healthcare
In plain terms
A weakness here would mostly expose their business/market datasets and customer account information rather than patient records, but a lapse could still leak commercially sensitive data and undermine trust.
They have an independent SOC 2 report and a published privacy program covering major US state laws and GDPR, showing baseline security discipline for a data-analytics vendor.
Certifications (public)
BAA & contract (from our records)
What we found
- Achieved SOC 2 Type I on June 7, 2023, and publicly stated intent to achieve SOC 2 Type II by end of 2023 (public confirmation of Type II completion not found).
- Business is healthcare commercial/market intelligence (provider, facility, and market data) — aggregated reference data rather than patient PHI, so a BAA is generally not required.
- Maintains a Privacy Center and state-specific privacy notices (CCPA, Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana) plus GDPR.
- No public evidence of HITRUST or ISO 27001.
Checklist: what might need doing
- Confirm whether SOC 2 Type II was completed and request the current report
- Confirm the data they provide is aggregated/reference data and contains no PHI (verify BAA is not needed)
- Ask about HITRUST or ISO 27001 status
- Review their subprocessor and data-sourcing disclosures
- Confirm contractual security and breach-notification terms
First-pass summary
Definitive Healthcare is a healthcare commercial-intelligence provider whose public posture confirms SOC 2 Type I (June 2023) with a stated Type II goal that could not be verified. Because it deals in aggregated market/provider data rather than patient PHI, a BAA is generally not required, lowering regulated-data risk. Coverage is on the lighter side; request the latest SOC 2 report and confirm no PHI exposure.
Compiled from public sources (www.definitivehc.comwww.definitivehc.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Accuhealth
In plain terms
If their security claims turn out to be weaker than advertised, patient vitals and identities we send them could be exposed and we'd be on the hook for the breach as the covered entity.
They openly state they are HIPAA-compliant and have a SOC 2 audit, which is the baseline you want from a company handling patient health data.
Certifications (public)
BAA & contract (from our records)
What we found
- Self-describes 'Evelyn' RPM platform as HIPAA-compliant and SOC 2-certified across marketing/FAQ pages, but with no evidence link.
- No dedicated trust center or public security page; SOC 2 type, scope, auditor and date are all unstated.
- No public mention of HITRUST or ISO 27001.
- Handles ePHI as an RPM vendor; BAA would be required but BAA availability is not documented on public pages.
Checklist: what might need doing
- Request the actual SOC 2 report and confirm whether it is Type I or Type II, its period, and the auditor.
- Obtain and review a signed BAA before any PHI flows.
- Ask whether HITRUST or a HIPAA Security Rule third-party assessment exists.
- Ask for pen test summary and data hosting/encryption details for the Evelyn platform.
First-pass summary
Accuhealth publicly claims its Evelyn RPM platform is HIPAA-compliant and SOC 2-certified, but provides no report, type, auditor, or trust center to verify it. The claim is plausible for an established RPM vendor but currently unverified beyond marketing copy. Standard next step is to request the SOC 2 report and BAA.
Compiled from public sources (www.accuhealth.techwww.accuhealth.tech). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Smart Meter
In plain terms
Even a strong vendor can slip — if a device or their network were compromised, a continuous stream of patients' vitals could be exposed, and we'd share the regulatory fallout.
They've passed an independent, rigorous SOC 2 Type II audit three years running and keep patient data on a private U.S.-only network, which is about as reassuring as it gets for a device RPM vendor.
Certifications (public)
BAA & contract (from our records)
What we found
- SOC 2 Type II for the third consecutive year (announced October 2025), audited by Schellman, a well-regarded SOC 2 firm — indicates a maturing, sustained program (initial SOC 2 in Sept 2023).
- Cellular-only RPM devices (iGlucose, iBloodPressure, iPulseOx, iScale) transmit over a dedicated private AT&T/Cisco network; company markets that data stays on a U.S. network and never leaves the country.
- Company has publicly campaigned on the risk of RPM devices sending patient data to China, positioning its U.S.-only data path as a differentiator.
- States compliance with HIPAA, FDA, FTC, Medicare and commercial payor requirements; SOC 2 and HIPAA badges displayed on site.
- No HITRUST or ISO 27001 certification mentioned; no formal online trust center portal (report is request-based).
Checklist: what might need doing
- Request the current SOC 2 Type II report and confirm the audit period and scope cover the devices/services we'd use.
- Obtain a signed BAA.
- Verify the U.S.-data-residency and private-network claims in the SOC 2 report / security docs.
- Confirm device firmware update and vulnerability management practices.
- Optionally ask about HITRUST roadmap for health-system parity.
First-pass summary
Smart Meter is one of the stronger vendors in this batch: independently audited SOC 2 Type II three years running (Schellman), HIPAA-compliant, FDA-registered cellular devices, and a differentiated U.S.-only private data network. No HITRUST/ISO 27001, and the SOC 2 report is request-based rather than in an online trust portal. Low residual risk once the report and BAA are on file.
Compiled from public sources (smartmeterrpm.comwww.morningstar.comwww.businesswire.comwww.businesswire.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Tenovi
In plain terms
If their platform or device hub were breached, the patient vitals flowing through it could be exposed, and as the covered entity we'd share responsibility for the incident.
They've completed an independent SOC 2 Type II audit, run continuous compliance monitoring, sign BAAs as a HIPAA business associate, and pay for outside penetration testing — a solid, mature security story for their size.
Certifications (public)
BAA & contract (from our records)
What we found
- SOC 2 Type 2 audit completed by Insight Assurance, with continuous compliance monitoring via Drata; progressed from SOC 2 Type 1 to Type 2.
- Explicitly identifies as a HIPAA-compliant Business Associate (i.e., willing to sign BAAs).
- Publicly states it has undergone third-party penetration testing to validate platform security.
- Provides RPM device gateway/ecosystem (cellular hub + connected devices) and an API, so it ingests and transmits patient vitals (PHI).
- No HITRUST or ISO 27001 certification mentioned; SOC 2 report is request-based (grc@tenovi.com) rather than posted in a self-serve trust portal.
Checklist: what might need doing
- Request the SOC 2 Type II report (grc@tenovi.com) and confirm period, scope, and any exceptions.
- Obtain a signed BAA.
- Ask for the most recent penetration test summary/attestation.
- Confirm device/API data flows, encryption, and hosting details.
- Ask about HITRUST plans if health-system procurement requires it.
First-pass summary
Tenovi presents a strong, well-documented posture: independent SOC 2 Type II (Insight Assurance) with continuous Drata monitoring, HIPAA business-associate status with BAAs, and third-party penetration testing. No HITRUST or ISO 27001, and the SOC 2 report is provided on request rather than via an online portal. Low residual risk once the report and BAA are in hand.
Compiled from public sources (www.tenovi.comwww.tenovi.comwww.businesswire.comwww.tenovi.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Waystar
In plain terms
Because they handle patients' billing and health-payment information, a breach could expose both medical and financial data for large numbers of patients at once.
They hold the healthcare gold-standard HITRUST certification plus SOC 2 Type II and PCI DSS, which together cover health-data security and payment-card security.
Certifications (public)
BAA & contract (from our records)
What we found
- Achieved HITRUST CSF Certification (announced April 8, 2021).
- Completed SOC 2 Type II examination (per Waystar's own disclosure).
- Holds PCI DSS compliance (relevant because it processes healthcare payments as a revenue-cycle/clearinghouse platform).
- As an RCM/clearinghouse, it routinely processes PHI and payment data, so a BAA is required.
- Maintains dedicated compliance staffing (e.g., Compliance Analyst roles) indicating an ongoing program.
Checklist: what might need doing
- Request current HITRUST CSF certification letter and validity dates
- Request current SOC 2 Type II report and review exceptions
- Request PCI DSS Attestation of Compliance (AoC)
- Execute a BAA
- Confirm subprocessor/data-flow list and breach-notification SLAs
First-pass summary
Waystar is a healthcare revenue-cycle/clearinghouse vendor with a strong, publicly verifiable posture: HITRUST CSF Certified (2021), SOC 2 Type II, and PCI DSS. It processes PHI and payment data, so a BAA is required. This is one of the better-attested vendors in this batch; confirm current dates on each certificate.
Compiled from public sources (www.waystar.comcareers.waystar.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Domo
In plain terms
Domo aggregates data from across the business into dashboards, so if PHI or sensitive metrics flow into it, a breach could expose a broad, centralized view of the company's data.
Domo holds an unusually complete set of certifications for a BI platform — SOC 2, ISO 27001, HIPAA, and HITRUST — covering the healthcare-grade controls needed to trust it with regulated data.
Certifications (public)
BAA & contract (from our records)
What we found
- Domo's security page states it completes third-party audits, compliance assessments, and annual penetration tests, with certifications including SOC 1, SOC 2, ISO 27001, ISO 27018, HIPAA, HITRUST, GDPR, and CCPA.
- HITRUST + HIPAA support means Domo can be used with healthcare/PHI data under appropriate agreements.
- No FedRAMP authorization indicated in public materials.
- TWC already uses Domo (thewiredconnection.domo.com) as a BI/analytics platform per internal context.
Checklist: what might need doing
- Request the current SOC 2 Type II report and confirm it is Type II (not Type I) with the audit period.
- Obtain the HITRUST certification letter and ISO 27001 certificate to verify scope covers TWC's deployment.
- Ensure a BAA is in place if any PHI is loaded into Domo datasets.
- Confirm data residency and any subprocessor list.
First-pass summary
Domo publicly advertises a broad, mature compliance stack (SOC 1, SOC 2, ISO 27001, ISO 27018, HIPAA, HITRUST, GDPR, CCPA) on its security page, making it well-suited to handle regulated data with the right agreements. No FedRAMP was found. As an existing TWC platform, the main action is collecting the actual reports/certificates and confirming SOC 2 report type and BAA coverage.
Compiled from public sources (www.domo.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Five9
In plain terms
Contact-center software records and routes live customer/patient phone calls, so a weakness could expose recorded conversations, health details, or payment card numbers spoken over the phone.
Five9 carries the security audits that matter most for phone-based data (SOC 2, ISO 27001, and top-tier PCI for card payments) and will sign a HIPAA business associate agreement.
Certifications (public)
BAA & contract (from our records)
What we found
- SOC 2 Type II audit under AICPA Trust Services Criteria (Security, Availability) for the cloud contact center.
- Level 1 PCI DSS Service Provider assessed annually by an independent QSA against all 12 requirements (v4.0.1).
- Acts as a HIPAA Business Associate with administrative, physical, and technical safeguards for PHI in transit and at rest; HITECH addressed.
- ISO 27001:2022 and ISO 27017:2015 certified; also references Cyber Essentials and CSA STAR.
- No public evidence of HITRUST certification found despite serving healthcare clients.
Checklist: what might need doing
- Obtain the current SOC 2 Type II report and PCI DSS Attestation of Compliance (AOC) from the Five9 Trust Center.
- Sign a BAA and confirm PHI-handling configuration (call recording, transcription, storage) before healthcare use.
- Ask Five9 directly whether HITRUST certification exists or is planned, since it is not publicly confirmed.
- Review call-recording retention and encryption settings against TWC HIPAA requirements.
First-pass summary
Five9 is a well-certified cloud contact-center vendor: SOC 2 Type II, ISO 27001:2022/27017, Level 1 PCI DSS v4.0.1, and HIPAA/HITECH Business Associate safeguards. HITRUST could not be verified publicly. Because it processes voice, recordings, and potentially PHI and card data, it is a higher-sensitivity supplier warranting BAA and PCI AOC review.
Compiled from public sources (trustcenter.five9.comwww.five9.comwww.five9.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Monday.com
In plain terms
Teams often paste sensitive project data, client info, or spreadsheets into Monday boards, so a gap could quietly expose a lot of scattered internal and customer information.
Monday.com publishes a full slate of annually renewed audits and privacy certifications, showing it takes security seriously and gets checked by outside auditors every year.
Certifications (public)
BAA & contract (from our records)
What we found
- SOC 1 Type II, SOC 2 Type II, and SOC 3, audited annually; reports available through the compliance hub.
- Broad ISO portfolio: 27001:2022, 27017, 27018, 27032, 27701.
- HIPAA listed among compliance programs (BAA-based, not an independent certification).
- Hosted on AWS and GCP across multiple availability zones with DR in separate regions; runs a managed private bug bounty program.
- No PCI DSS or HITRUST certification listed on the trust center.
Checklist: what might need doing
- Pull the current SOC 2 Type II report from trust.monday.com and confirm the audit period is recent.
- Sign a BAA and confirm HIPAA configuration before any PHI is stored on boards.
- Set data-governance rules so staff do not paste PHI/PII into free-form boards unless approved.
- Confirm ISO 27001 certificate scope covers the purchased product.
First-pass summary
Monday.com maintains a strong, broad compliance posture: SOC 1/2/3, a wide ISO 27001-family portfolio, and HIPAA/GDPR programs, all surfaced on a public trust center with annual audits. No PCI DSS or HITRUST is listed. Main risk is human data-handling since boards accept arbitrary content.
Compiled from public sources (trust.monday.commonday.commonday.com). A production run reads the actual documents in the supplier folder. Security still makes the final call.
Twilio
In plain terms
Twilio carries messages, calls, and verification codes, so if it were compromised an attacker could intercept communications or the codes used to log into accounts.
Twilio has a strong, broad certification set — SOC 2 Type II, ISO 27001 and related ISO standards, and PCI DSS Level 1 — and offers HIPAA business-associate agreements for eligible products.
Certifications (public)
BAA & contract (from our records)
What we found
- Twilio Trust Center lists SOC 2 Type II, ISO/IEC 27001, ISO 27017, ISO 27018, and PCI DSS Level 1.
- Twilio runs a risk-based security program built on the ISO/IEC 27001 ISMS.
- HIPAA: Twilio supports HIPAA-eligible workflows and offers a BAA for specific eligible products/configurations — not all products are HIPAA-eligible, so scope must be confirmed.
- No HITRUST CSF certification confirmed from public sources (unable to verify — mark unknown).
- SOC 2 Type II and pen-test reports are available through the trust center, typically under NDA.
Checklist: what might need doing
- Confirm exactly which Twilio product(s) TWC uses and whether each is HIPAA-eligible before sending any PHI (e.g., in SMS/voice content).
- Sign a BAA covering the specific eligible products.
- Pull the current SOC 2 Type II report from the trust center (under NDA) and review exceptions.
- Verify HITRUST status directly if HITRUST is a TWC requirement (not publicly confirmed).
First-pass summary
Twilio maintains a strong, publicly documented compliance posture (SOC 2 Type II, ISO 27001/27017/27018, PCI DSS Level 1) via its trust center at security.twilio.com and supports HIPAA BAAs for eligible products. HITRUST certification could not be verified from public sources and is marked unknown. The key diligence step is confirming that the specific Twilio products TWC uses are HIPAA-eligible before any PHI touches them.
Compiled from public sources (security.twilio.comwww.twilio.comhelp.twilio.comtrustlists.org). A production run reads the actual documents in the supplier folder. Security still makes the final call.